File name:

Profwiz.exe

Full analysis: https://app.any.run/tasks/a332ddea-1adf-4e42-926a-26c724182426
Verdict: Malicious activity
Analysis date: November 23, 2022, 01:28:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

035ECE79639F70C7B596C74FB9EA435F

SHA1:

1CAE2512499A06B4EF5F8E0318349238B37F5567

SHA256:

652EE5384F9ECE3D759FE4D14BAC14201D7693C0953031F1FC663EB57F271C5B

SSDEEP:

24576:3d4s9Au5KK3r3v+8KLKz5diorQLQnLtpH4C4dK5Ah4BOO8yQ:3d48Au5KKz+8KLKz5dVMLQ5pH4CuK5by

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Profwiz.exe (PID: 3488)
    • Application was dropped or rewritten from another process

      • UserProfileMigrationService.exe (PID: 3992)
  • SUSPICIOUS

    • Executes as Windows Service

      • UserProfileMigrationService.exe (PID: 3992)
    • Executable content was dropped or overwritten

      • Profwiz.exe (PID: 3488)
  • INFO

    • Reads the computer name

      • Profwiz.exe (PID: 3488)
      • UserProfileMigrationService.exe (PID: 3992)
    • Checks supported languages

      • Profwiz.exe (PID: 3488)
      • UserProfileMigrationService.exe (PID: 3992)
    • Drops a file that was compiled in debug mode

      • Profwiz.exe (PID: 3488)
    • Creates files in the program directory

      • Profwiz.exe (PID: 3488)
    • Process checks LSA protection

      • UserProfileMigrationService.exe (PID: 3992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2020-Nov-14 17:22:26
Detected languages:
  • English - United Kingdom
  • English - United States
Debug artifacts:
  • C:\Users\David\source\repos\User Profile Wizard 3.0\Free Release\Profwiz.pdb
Build: 21.1.1265
CompanyName: ForensiT Limited
FileDescription: ForensiT User Profile Wizard
FileVersion: 21.1.1265.0
InternalName: Profwiz
LegalCopyright: Copyright © ForensiT 2002-2020
OriginalFilename: Profwiz.exe
ProductName: User Profile Wizard
ProductVersion: 21.1.1265.0

DOS Header

e_magic: MZ
e_cblp: 144
e_cp: 3
e_crlc: -
e_cparhdr: 4
e_minalloc: -
e_maxalloc: 65535
e_ss: -
e_sp: 184
e_csum: -
e_ip: -
e_cs: -
e_ovno: -
e_oemid: -
e_oeminfo: -
e_lfanew: 304

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 4
TimeDateStamp: 2020-Nov-14 17:22:26
PointerToSymbolTable: -
NumberOfSymbols: -
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
4096
127276
127488
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.53661
.rdata
135168
53018
53248
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.76445
.data
188416
6432
3072
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.42954
.rsrc
196608
1025808
1026048
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
6.43355

Resources

Title
Entropy
Size
Codepage
Language
Type
1
3.96446
1384
UNKNOWN
English - United Kingdom
RT_ICON
2
6.43717
2216
UNKNOWN
English - United Kingdom
RT_ICON
3
6.12722
3752
UNKNOWN
English - United Kingdom
RT_ICON
4
5.36711
1128
UNKNOWN
English - United Kingdom
RT_ICON
5
5.6209
4264
UNKNOWN
English - United Kingdom
RT_ICON
6
5.16137
9640
UNKNOWN
English - United Kingdom
RT_ICON
7
2.02383
296
UNKNOWN
English - United Kingdom
RT_ICON
8
4.197
744
UNKNOWN
English - United Kingdom
RT_ICON
9
4.05136
488
UNKNOWN
English - United Kingdom
RT_ICON
10
3.5826
296
UNKNOWN
English - United Kingdom
RT_ICON

Imports

ADVAPI32.dll
GDI32.dll
KERNEL32.dll
MPR.dll
NETAPI32.dll
OLEAUT32.dll
RPCRT4.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start profwiz.exe userprofilemigrationservice.exe profwiz.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1284"C:\Users\admin\AppData\Local\Temp\Profwiz.exe" C:\Users\admin\AppData\Local\Temp\Profwiz.exeExplorer.EXE
User:
admin
Company:
ForensiT Limited
Integrity Level:
MEDIUM
Description:
ForensiT User Profile Wizard
Exit code:
3221226540
Version:
21.1.1265.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\profwiz.exe
3488"C:\Users\admin\AppData\Local\Temp\Profwiz.exe" C:\Users\admin\AppData\Local\Temp\Profwiz.exe
Explorer.EXE
User:
admin
Company:
ForensiT Limited
Integrity Level:
HIGH
Description:
ForensiT User Profile Wizard
Exit code:
0
Version:
21.1.1265.0
Modules
Images
c:\users\admin\appdata\local\temp\profwiz.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
3992C:\ProgramData\UserProfileMigrationService.exeC:\ProgramData\UserProfileMigrationService.exe
services.exe
User:
SYSTEM
Company:
ForensiT Limited
Integrity Level:
SYSTEM
Description:
ForensiT User Profile Migration Service
Exit code:
0
Version:
21.1.1264.0
Modules
Images
c:\programdata\userprofilemigrationservice.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\rpcrt4.dll
Total events
64
Read events
58
Write events
6
Delete events
0

Modification events

(PID) Process:(3488) Profwiz.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\Profwiz.exe
Operation:writeName:DumpCount
Value:
16
(PID) Process:(3488) Profwiz.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\Profwiz.exe
Operation:writeName:DumpFolder
Value:
%ALLUSERSPROFILE%\ForensiT\Error Reporting
(PID) Process:(3488) Profwiz.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\Profwiz.exe
Operation:writeName:DumpType
Value:
1
(PID) Process:(3488) Profwiz.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\UserProfileMigrationService.exe
Operation:writeName:DumpCount
Value:
16
(PID) Process:(3488) Profwiz.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\UserProfileMigrationService.exe
Operation:writeName:DumpFolder
Value:
%ALLUSERSPROFILE%\ForensiT\Error Reporting
(PID) Process:(3488) Profwiz.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\UserProfileMigrationService.exe
Operation:writeName:DumpType
Value:
1
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3488Profwiz.exeC:\ProgramData\UserProfileMigrationService.exeexecutable
MD5:E3529A23E2A0852D36B6674CF3B201AD
SHA256:4B487D11DF5074DEE1DDDAAB4487014A76D160E2B87AE28EDCFFDF1B7E945F29
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
Profwiz.exe
Starting service with SERVICE_ALL_ACCESS
Profwiz.exe
Service has started
UserProfileMigrationService.exe
User Profile Wizard Service Started (Direct.)
UserProfileMigrationService.exe
DEBUG: ProcessPipeServerRequest(). Request ID: 10